git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] daemon: Skip unknown "extra arg" information

From
Junio C Hamano <gitster@pobox.com>
Date
Jun 7, 2009, 20:29 UTC
Message-ID
<7vfxebaiub.fsf@alter.siamese.dyndns.org>
In-Reply-To
<200906072056.08680.j6t@kdbg.org>
Johannes Sixt <j6t@kdbg.org> writes:
Show 14 quoted lines
> On Freitag, 5. Juni 2009, Shawn O. Pearce wrote:
>> Actually, we're already f'kd.  We can't change the protocol like
>> we had hoped.  I still think this should go in maint.
>>
>> --8<--
>> daemon: Strictly parse the "extra arg" part of the command
>>
>> Since 1.4.4.5 (49ba83fb67 "Add virtualization support to git-daemon")
>> git daemon enters an infinite loop and never terminates if a client
>> hides any extra arguments in the initial request line which is not
>> exactly "\0host=blah\0".
>
> I see you applied this to maint. Since this patch actually fixes a 
> DoS-exploitable bug, shouldn't it be applied all the way back to 1.4.4.5?

I personally do not have the bandwidth to worry about anything older than say 1.6.0. Interested parties (read: distro packagers who pride themselves for their LTS) can do that themselves.

Previous: Johannes Sixt
Message 7 of 7 in “daemon: Skip unknown "extra arg" information”
  1. daemon: Skip unknown "extra arg" informationShawn O. Pearce, Jun 4, 2009
  2. Junio C HamanoJun 5, 2009
  3. Shawn O. PearceJun 5, 2009
  4. Jakub NarebskiJun 5, 2009
  5. Sergey VlasovJun 5, 2009
  6. Johannes SixtJun 7, 2009
  7. Junio C HamanoJun 7, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.